What is the Zscaler Client Connector (ZCC)?
The Zscaler Client Connector (ZCC) is the endpoint agent of the Zscaler platform. It captures traffic from endpoint devices and forwards it to the Zero Trust Exchange. A single client connects three services: internet traffic is inspected through Zscaler Internet Access (ZIA), access to internal applications runs through Zscaler Private Access (ZPA), and Zscaler Digital Experience (ZDX) receives telemetry on device, network and applications. ZCC authenticates the user against the connected identity provider and applies centrally managed profiles that determine forwarding behaviour per environment. For IT operations, the client is therefore the point where security, connectivity and troubleshooting come together.
Zscaler Client Connector in detail
After sign-in, the client builds tunnels to the Zscaler cloud depending on its configuration and forwards the captured traffic there. Two centrally managed building blocks control how this happens: the forwarding profile determines how internet traffic is routed, for example in tunnel mode or through a PAC file, while the app profile governs platform-specific settings and exceptions. The client can also recognise defined trusted networks and adjust its behaviour there.
ZCC is managed through its own admin portal, where profiles, policies and client versions are maintained centrally. The client runs on common desktop and mobile platforms, including Windows, macOS, Linux, iOS and Android. Whether users may disable the client themselves can be restricted by policy: Zscaler provides separate passwords for this, for example for uninstalling the client and, separately, for turning off individual services such as ZDX or endpoint DLP. Removing a device only signs the client out; it does not uninstall it.
Why ZCC matters in Zscaler operations
A large share of Zscaler tickets lands with the client first: 'no internet', 'application unreachable', 'everything is slow'. The first useful question is almost always: is ZCC signed in, which profile is active, is the tunnel up? Classic causes such as a captive portal on hotel Wi-Fi explain many cases. Anyone who cannot see this status is left guessing or has to escalate to administrators.
The client is also business-critical across the whole fleet: outdated versions cause known bugs, and as the enforcement point for security policy it must not be disabled unnoticed. A disabled client means either uninspected traffic or missing access, depending on the architecture. For evidence purposes, what counts is being able to prove the actual state of clients, not just the policies on paper.
Common sources of error
- Outdated client versions in the fleet: older ZCC builds behave differently than expected and produce error patterns that are hard to reproduce.
- Profile does not match the environment: a forwarding profile that works on the corporate network causes connection problems at home or behind a captive portal.
- Conflicts with other software: VPN clients or endpoint security products installed in parallel get in the way of tunnel setup.
- Disabled clients without control: if users can turn off ZCC freely, uninspected traffic results without anyone noticing.
ZCC in practice: what CentaurNexus contributes
CentaurNexus puts the client context to work for support: User Support Center shows a 360-degree user finding across ZIA, ZPA and ZDX in one view, without the helpdesk needing Zscaler admin rights. Connectivity Triage Map combines the ZDX chain with policy status and names the cause in plain language: ISP, Wi-Fi, device or Zscaler. The guide below shows how this looks in daily practice: Is it Zscaler or the Wi-Fi?. If a compromised device needs to be removed, Emergency User Isolation isolates it from ZIA and ZPA. All write actions are auditable, optionally with four-eyes approval.
Related terms
Frequently asked questions about the Zscaler Client Connector
The client signs the user in to the Zscaler platform, captures the device's traffic and forwards it according to the centrally managed profiles: internet traffic goes to ZIA for inspection, access to internal applications goes to ZPA. It also supplies telemetry for ZDX, which is used to measure the digital user experience.
Zscaler provides the Client Connector for common desktop and mobile platforms, including Windows, macOS, Linux, iOS and Android. The feature set and configuration options differ by platform. The authoritative source is the official compatibility list in the Zscaler Help Portal, which documents supported versions and platform-specific details.
That depends on the configuration. Administrators can restrict disabling or signing out by policy, for example with an additional password. In well-run environments this is the norm, because a disabled client means either uninspected traffic or missing access to internal applications, depending on the setup.
A VPN client builds a tunnel into a network where the user gets broad access. ZCC instead connects to the Zscaler cloud: internet traffic is inspected inline there, and internal applications become reachable individually and on a policy basis through ZPA. The network itself stays hidden, which significantly reduces the attack surface.
It helps to look at the chain: is the client signed in, which profile is active, is the tunnel up, and what do the ZDX values show for device and network? If the telemetry shows a healthy device and a stable network, the cause is more likely with the application or the provider than with the client.
- Zscaler Help Portal: Configuring Passwords for Access in Unattended Mode - help.zscaler.com/zscaler-client-connector/configuring-passwords-access-unattended-mode
- Zscaler Help Portal: ZIA documentation, help.zscaler.com/zia
- Zscaler Help Portal: ZPA documentation, help.zscaler.com/zpa
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.